A security lead receives OVHcloud's ISO 27001 certificate, ticks the compliance box, and migrates a business application to Public Cloud. Three months later, the auditor asks whether automated backups, the admin panel, and managed support sit inside the certified scope. Silence. The badge was real; the coverage was partial.
The useful question is not "Does OVHcloud have ISO 27001?" — it does, on part of the range. It is: *which service, region, and adjacent functions are actually audited for your architecture?*
What an ISO 27001 certificate guarantees — and excludes
ISO/IEC 27001 does not certify "a host" wholesale. It certifies an information security management system (ISMS) applied to a scope defined by the organisation: sites, processes, products, regions, sometimes legal entities.
At a provider as broad as OVHcloud, that scope may cover Hosted Private Cloud lines or named datacenters while leaving other ranges, preview services, or sub-processors outside the certificate.
An ISO 27001 logo on a product page is not proof. It is an invitation to open the certificate.
Reading OVHcloud scope in four passes
Before signing, request three documents: the certificate (number, expiry, certification body), the statement of applicability, and where available the scope annex listing services and sites.
| Element | What to verify | Warning sign |
|---|---|---|
| Exact product | Public Cloud, Hosted Private Cloud, bare metal, email, object storage | "OVHcloud cloud" with no product line |
| Region / DC | Gravelines, Roubaix, Strasbourg, etc. | Chosen region missing from annex |
| Related functions | Backups, snapshots, load balancer, IAM | Managed services not mentioned |
| Sub-processors | L3 support, CDN, third-party cloud | Opaque chain |
| Contracting entity | OVH SAS, local subsidiary | Contract signed with entity outside scope |
Then map your real architecture: database, files, logs, CI/CD pipelines, admin access. Every uncovered component remains your risk to document in the compliance review.
Public Cloud, private cloud, shared hosting: three possible scopes
OVHcloud does not sell a single "certified cloud." A Public Cloud project (instances, managed Kubernetes, object storage) does not carry the same documented guarantees as Hosted Private Cloud or legacy shared hosting.
In practice:
- Match the SKU you buy to the exact certificate or SoA line.
- Verify the region: a covered French datacenter does not automatically cover a Canada replica or an unlisted zone.
- Isolate managed services: automated backups, WAF, DBaaS may run on separate teams or stacks.
- Cross-check HDS if you process health data: ISO 27001 does not replace a valid HDS attestation on the right product.
Our OVHcloud profile marks ISO 27001 in the public matrix — a starting point, not audit evidence.
Common due diligence mistakes
Confusing GDPR compliance with ISO 27001. GDPR governs personal data processing; ISO attests to an ISMS. OVHcloud may be GDPR-aligned via its DPA while ISO scope is narrower than your stack.
Assuming backup coverage. Recovery copies are often gap number one: stored elsewhere, restored by a third tool, or operated by the customer alone.
Ignoring shared responsibility. On Public Cloud, network configuration, IAM rights, and client-side encryption remain your duty — outside provider scope if misconfigured.
Comparing hosts on the logo alone. For a serious benchmark, read ISO 27001 in Europe: compare a certificate's scope and confront annexes on an identical scenario.
The peak: the certificate does not know which button you clicked
That is the gap trust pages gloss over: certification attests a system OVHcloud describes, not the configuration you assembled in the panel.
Decide and move forward without blind spots
List your stack: compute, storage, network, backups, logs, admin access. Request certificate, SoA, and scope annex for the target product and region. Mark in red anything missing or vague; add contractual measures or change product.
Test a restore and document who operates what during an incident. Compare via our compare tool and the guide GDPR, HDS, SecNumCloud if the project handles sensitive data. Browse the directory to benchmark OVHcloud against other certified providers on measurable criteria.
Frequently asked questions
Is OVHcloud ISO 27001 certified across its entire product range?
No. Certification applies to a defined ISMS scope. Each product and region must be verified in the certificate or SoA — a global logo is not enough.
Where do I find OVHcloud's exact scope?
Request the valid certificate, statement of applicability, and annex listing services and sites. Marketing pages do not replace those documents.
Does OVHcloud ISO 27001 cover health data?
Not alone in France: HDS is a separate obligation. OVHcloud offers HDS options, but verify your product and region on the HDS attestation, not only ISO 27001.
How do I compare OVHcloud with another certified host?
Align the same technical scenario, then compare written scopes. Two ISO 27001 certificates can imply very different guarantees.
Next time a sales rep says "we are ISO 27001", reply: show me the line that covers my product, my region, and my backups.
